Security Guides
What leaked is when you travel and on which train — the Trenitalia data breach and how to spot fake delay-refund messages
Italian rail operator Trenitalia notified customers, first on June 26, 2026, of unauthorised access to personal data linked to tickets: itineraries, contact details and dates of birth, but not passwords or card data. What travellers should do, from official guidance.
For: anyone who has bought Italian rail tickets or passes from Trenitalia, including tourists who booked a Frecciarossa or another train for a trip to Italy, and anyone who has received a text or email about a "train delay refund". This article is based on the customer notices Trenitalia published, its delay-compensation guidance, and official pages from the Italian data protection authority (Garante), CERT-AGID and the Italian Postal and Communications Police (Polizia Postale). It does not cover attack techniques.
What travellers should do today
Treat any message that mentions your trips as suspect, and do not open its links
In its notice, Trenitalia warns that given the type of data involved, you may receive fraudulent messages that refer to your journeys, and asks customers to be especially careful with messages that request personal or financial data or contain unexpected links or attachments. A correct route or date does not prove a message is genuine. To check, type trenitalia.com into your browser yourself or open the official app and look at your booking there (basics in What is phishing?).
Claim delay compensation only through official channels
According to Trenitalia, compensation for delays on Frecce (high-speed) and Intercity trains is requested within one year of the journey via the web form or the "Richiedi Indennizzo" function on its website, the Trenitalia app, ticket offices, the travel agency that issued the ticket, the call centre, or by post. For regional digital tickets (Biglietto Digitale Regionale), eligible compensation is paid automatically to the card used for the purchase, with no request needed. Nowhere in that guidance does a refund work by clicking a link and entering card details.
Never give out passwords or card numbers, whoever asks
Trenitalia states that it will never contact you to ask for passwords or payment data. The Italian data protection authority (Garante) likewise advises never to reply to texts asking for your tax code (codice fiscale), PINs, card number, card security code or one-time passwords.
If you entered card details, call your card issuer right away
The Garante advises that if you may have handed over bank or card details in an SMS scam, you should contact your bank or card issuer immediately through known, trusted channels to report it and block transactions, and report to the police if money was taken. Checking statements often and turning on transaction alerts helps you notice sooner. For a card issued outside Italy, call the number on the back of the card.
Contact Trenitalia only through the form named in its notice
Trenitalia has set up a dedicated support channel: its complaints and suggestions web form (reclami-e-suggerimenti.trenitalia.com), option "Privacy – Gestione dei dati personali", entering the reference code from the notice. For phone contact, use the call centre number on Trenitalia's own website, never a number given in a message.
Report suspicious messages
The Italian Postal and Communications Police (Polizia Postale) accepts phishing reports through the "Segnala online" form on commissariatodips.it (in an emergency, call 112 or 113). Outside Italy, use your own country's reporting channel; in Japan, for example, the Council of Anti-Phishing Japan takes reports (attach a screenshot for texts).
Route, date, time, ticket number
+ email address and phone number
↓→
"Your train on the 12th was delayed: claim your refund"
→ Skip the link; open the app or trenitalia.com yourself
Name, date and place of birth
(tax code in one of the notices)
↓→
A call that "verifies" you with your real birth date
→ Knowing it proves nothing. Hang up, call the official line
Loyalty card code, employer
(only for tickets that had them)
↓→
"Your points expire" / "confirm your corporate fare"
→ Check points in the official app; never enter card data
Not included (per Trenitalia): login data, passwords, card number, expiry date, security code
What happened (from Trenitalia's notices)
Everything below is as stated in the customer notices Trenitalia published on its website (a "communication of a personal data breach" under Article 34 of the GDPR). Three versions are published, depending on the ticket: tickets sold by Trenitalia alone, tickets jointly controlled with Trenitalia France, and tickets jointly controlled with Consorzio Unico Campania, the body behind the Campania region's shared UnicoCampania tickets.
Date not disclosed
Trenitalia detected a cybersecurity incident caused by unidentified external parties, resulting in unauthorised access to some personal data linked to travel tickets. The company says that on detection it immediately stopped the anomaly, secured its systems and further strengthened its controls.Analysis period
Trenitalia's IT teams carried out in-depth technical analysis to identify precisely who was potentially affected. The company says this took time because improper access had to be reconstructed in detail, and that it notified affected customers once the work was complete.June 26, 2026
According to the notices for jointly controlled tickets, the date on which Trenitalia communicated this event to customers.Later
Trenitalia sent notices on behalf of itself and Trenitalia France, and of itself and Consorzio Unico Campania, for jointly controlled tickets. Both state it is "the same event" communicated on June 26.
- Identity
- Passenger's name, date of birth and place of birth; the buyer's name if different
- Contact
- Email address, phone number
- Itinerary
- Information linked to the ticket (for example route, date, time, ticket number) and data related to generating the ticket
- Other (Trenitalia and Trenitalia France notices)
- Loyalty card code linked to the ticket, employer company or organisation, type of offer or service linked to the ticket and the data needed to use it, identity document details
- UnicoCampania notice
- Also lists the tax code (codice fiscale) and gender; it does not list employer or identity document details
- Not included
- Account access data, personal credentials, and payment information (card number, expiry date, security code)
- Reports
- Notified to the Italian data protection authority (Garante) and CSIRT Italia; criminal complaint filed with the public prosecutor at the Court of Rome
How to read the list: it depends on the ticket and on what was held
The notices say the categories apply only where such data was held in Trenitalia's systems in connection with the ticket. An employer, for example, relates to business tickets, and a loyalty card code only to tickets with a linked card. Of the three published notices, only the UnicoCampania one lists the tax code. Some media reports merge the categories or give dates for the incident; this article uses only what Trenitalia's notices say.
An itinerary is both a scam script and a calendar of when you are away
Leaks of names and email addresses are common. What is different here is the itinerary. Knowing when, from where, to where and on which train someone travelled enables two things.
What a list without itineraries enables
- "There is a problem with your account"
- "Your points are about to expire"
- Easy to dismiss if it doesn't match anything you did
What a list with itineraries enables
- "Your train to Naples on the 3rd was delayed: claim your refund"
- "Ticket no. X needs a change to be confirmed"
- The people who actually took that train are the most likely to believe it
First, refund scams become far more convincing. In July 2026, CERT-AGID (the CERT of Italy's digital agency) reported an SMS campaign that used Trenitalia's name and a fake refund for a delayed train to steal phone numbers and credit card details. Whether that campaign used data from this breach has not been published. But a message with the right route and date is much harder to doubt.
Second, a point this site wants to add as its own view: an itinerary is also a record of when a person is away from home. Knowledge of travel plans could be used in messages such as "about your home while you are away next week", in calls claiming to act for someone on a business trip, or in messages to family members while the traveller is abroad. The defence is simple: never treat knowledge of someone's travel plans as proof of identity or trustworthiness. It also helps to tell your family: "even if a message knows my itinerary, don't send money or information until you've reached me directly."
This site's view: learn the one genuine refund path, and you never need to judge the fakes
Tips for spotting fake texts (misspelled links, odd wording) stop working as scammers get better. A more reliable approach is to know the genuine process in advance. With Trenitalia, delay compensation is either requested by you through its website, app or ticket offices, or, for regional digital tickets, paid automatically to the card you bought with. "Open this link and enter your card number to get your refund" fits neither, so you can call it fake without reading any further.
There is a lesson for organizations sending breach notices too: leave login links out of the notice and state that refunds and compensation will never require card details. That gives customers a simple rule. Trenitalia's notice does state that it will never ask for passwords or payment data, which is a step in that direction. The same idea came up in the French case where a list of ID applicants leaked (the France Titres (ANTS) breach).
Fake messages using travel booking details have also been a problem in the accommodation sector (the Booking.com data breach). For another European case this year, in which logged-in users of the UK company registry could see other companies' non-public data, see the Companies House WebFiling flaw.
Sources (public record)
The facts in this article come from the public sources below. Speculation in media coverage and undisclosed figures, dates or causes are not used.
- Trenitalia, "Comunicazione di violazione dei dati personali ai sensi dell'art. 34 del Regolamento UE 679/2016" (tickets sold by Trenitalia alone) — trenitalia.com
- Trenitalia and Trenitalia France, the same notice (states it is the event communicated on June 26) — trenitalia.com
- Trenitalia and Consorzio Unico Campania, the same notice (lists tax code and gender) — trenitalia.com
- Trenitalia, "Indennità per ritardo del treno" (delay compensation and how to claim) — trenitalia.com
- CERT-AGID, "Sintesi riepilogativa delle campagne malevole nella settimana del 4 – 10 luglio" (July 10, 2026) — cert-agid.gov.it
- Garante per la protezione dei dati personali, "Smishing: i suggerimenti del Garante" — garanteprivacy.it
- Polizia Postale, "Segnala online" — commissariatodips.it
- Council of Anti-Phishing Japan, phishing reports (Japanese) — antiphishing.jp
Update history
2026-09-30: First version, based on the three customer notices published by Trenitalia, its delay-compensation guidance, CERT-AGID's weekly summary (July 10), and guidance from the Garante and the Italian Postal Police. The number of people affected, when the incident happened or was detected, and the technical cause have not been officially published; this article will be updated if they are.
Read next
- Preparing for fake messages after a list leaks: The France Titres (ANTS) breach (France)
- Fake messages using travel booking details: The Booking.com data breach
- Another European case this year: The Companies House WebFiling flaw (UK)
- Spotting fake messages: What is phishing? / Protecting devices while travelling: Securing a laptop you carry around
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat data was exposed in the Trenitalia breach?
According to Trenitalia's notice, where held in its systems in connection with a ticket, the data that may have been accessed includes the passenger's name, date and place of birth (and the buyer's name if different), email address and phone number, itinerary data such as route, date, time and ticket number, the loyalty card code linked to the ticket, the employer company or organisation, the type of offer or service linked to the ticket and data needed to use it, identity document details (estremi documento d'identità), and data related to generating the ticket. The notice for UnicoCampania tickets in the Campania region also lists the tax code (codice fiscale) and gender.
QWere passwords or credit card details exposed?
Trenitalia says account access data, personal credentials and payment information (such as card number, expiry date and security code) were not involved.
QHow many people were affected?
Trenitalia's notice does not give a number. The company says precisely identifying the people potentially involved required in-depth technical analysis by its IT teams, and that it notified affected customers once that work was complete. This article does not use figures that have not been officially published.
QI bought Trenitalia tickets as a tourist. Could I be affected?
The notice concerns personal data linked to Trenitalia tickets and does not distinguish customers by nationality. Trenitalia has notified affected customers individually (the notices for jointly controlled tickets refer to a reference code sent by SMS). Even without a notice, it is safest to assume that the email address and phone number you used for Trenitalia bookings may receive messages that mention your trips.
QWhat caused the breach?
Trenitalia describes a cybersecurity incident caused by unidentified external parties (soggetti esterni non identificati). It says it stopped the anomaly, secured its systems and strengthened controls, but it has not published the technical cause. It notified the Italian data protection authority (Garante) and CSIRT Italia and filed a complaint with the public prosecutor at the Court of Rome.
QI got a text about a refund for a delayed train. Is it real?
In July 2026, CERT-AGID (the CERT of Italy's digital agency) reported an SMS scam that used Trenitalia's name and a fake refund for a delayed train to steal phone numbers and credit card details. No link between that scam and this breach has been published. According to Trenitalia, delay compensation is requested by the passenger through its website form, app, ticket offices and other official channels, or for regional digital tickets is paid automatically to the card used to buy the ticket. Do not open the link; open trenitalia.com or the app yourself.